← Back to the feed

Microsoft catches hackers exploiting Zimbra bug before disclosure

The Register ·

Microsoft tracked attackers exploiting a critical flaw in Zimbra Collaboration Suite before it was publicly disclosed. The unauthenticated vulnerability could let attackers run commands on exposed mail servers by sending a crafted email, making it a serious risk for affected organisations.

Microsoft saw scanning activity from 28 July to 7 August; the flaw was fixed on 20 July in Zimbra version 10.1.20, but disclosed publicly on 13 August. Attackers deployed remote access tools, sought credentials and mailbox data, and in some cases gained root access; Microsoft could not confirm whether one attempted transfer of mailbox backups succeeded. The flaw affects servers with Zimbra’s optional SNMP monitoring package and notifications enabled, and Microsoft advised administrators to update or disable those features.

  • Hackers probed a Zimbra flaw before its public disclosure.
  • Attacks targeted credentials, mailboxes and server access.
  • Updating or disabling SNMP features reduces exposure.

New here? Start with this

Zimbra Collaboration Suite is email and team collaboration software used by many organisations worldwide. A critical security flaw was discovered in this software that allows unauthenticated attackers to run commands on exposed mail servers by sending a specially crafted email. This is extremely serious because mail servers typically contain sensitive corporate and personal information.

The flaw was patched by Zimbra on 20 July, but details were not publicly disclosed until 13 August. This gap between patching and public disclosure is significant because some attackers exploit vulnerabilities during this period, before most organisations have had time to update their systems.

The vulnerability specifically affects Zimbra servers with optional monitoring and notification features enabled. Organisations should update to the latest version immediately, or disable these optional features.

Cybersecurity Technology

Read the full article at the source →